Candidate multi-factor authentication (MFA)
Table of Contents
The candidate multi-factor authentication setting ensures that candidate conversations are kept private because they often contain personal data, such as links to an offer or their resume. In order to protect candidate information and prevent unauthorized individuals access to their conversations, this setting requires that candidates enter a verification code to access specific links within their candidate conversation for additional security.
This setting is enabled by default.
Configuration
By default, this setting is automatically enabled and will allow a candidate to be authenticated for 10 minutes. During this time, a candidate will not have to re-authenticate themselves until the session ends. After 10 minutes, the candidate will have to re-verify themselves with a new verification code.
If the timeframe for this setting needs to be adjusted or if you want this setting disabled, users with full access to Client Setup can complete the below steps.
- Select All Apps in the top left corner of the header and then Settings from its drop-down menu.
- When the Settings page opens, select Client Setup under the Paradox Tools section.
- Client Setup will then open. From the left panel, scroll down to and open the More section.
- Find the Candidate’s private conversation setting. From there, complete one of the following actions:
- Turn off this setting – To disable this setting, toggle it off.
-
Update the expiration timeframe – From the Expire At selector, choose one of the following options:
- Immediately
- 10 Minutes (default)
- 6 Hours
- 12 Hours
- 24 Hours
- 48 Hours
- 72 Hours
- Save the page.
Regardless of whether candidate conversations are private or if candidate MFA is otherwise disabled, survey links sent to candidates will always require the candidate to enter a verification code. This is an intentional security measure and applies to all survey links.
The Verification Code Primary Contact Method setting controls whether candidates receive two-factor authentication (2FA) verification codes only through their primary contact method after the Secure Login page. This applies to SMS, Email, and WhatsApp.
If you want to enable or disable this setting, users with full access to Client Setup can complete the below steps.
- Select All Apps in the top left corner of the header and then Settings from its drop-down menu.
- When the Settings page opens, select Client Setup under the Paradox Tools section.
- Client Setup will then open. From the left panel, scroll down to and open the More section.
- Enable or disable the Verification Code Primary Contact Method setting.
- Note: By default, this setting is off, and candidates continue to see every available verification code option.
- Save the page.
Notes:
- If a candidate has unsubscribed from their primary contact method, Paradox does not send a code through another channel. The candidate is prompted to update their communication preferences before a new code is sent.
- If a candidate's Primary Contact Method is set to Email but their profile does not include an email address, they see a message asking them to update their Primary Contact Method or provide valid contact details before continuing.
Enter verification code
When a candidate accesses a link that includes their conversation history, they receive a verification code from their phone number or email address.
To access a link within their conversation history, the candidate needs to follow the steps below:
- Click on the link to access the Secure Login page.
- Select their preferred communication method to receive the verification code.
- Note: Depending on their communication preferences, they may see options for email, SMS, or WhatsApp (if enabled).
- From the verification page, enter in the one-time code sent to your preferred communication preference.
The candidate is then able to access the link, and they are redirected to their desired page.
Multilingual candidates are shown this page in their preferred language by default. A language dropdown is also now available on this page, allowing the candidate to select their preferred language for the verification process.
All PII information, such as email address and phone number, is protected in the Enter Verification Code page.
Verification code SMS autofill
When completing 2FA on a supported mobile device (iOS or Android), candidates can use the automated keyboard suggestion to instantly enter their verification code. This feature is available across all Paradox web pages that require a verification code.
Expiration logic
- The candidate’s verification code will be active for only one hour. After this time, the candidate will have to request a new verification code to open any of the below URLs.
- The expiration time set for the account is based on the session cached in the browser. If a candidate authenticates themself and then closes their browser before opening a new URL within the set expiration time, they will have to re-authenticate themself, as the browser that they authenticated themself on was closed.
- Note: If the candidate authenticates themself via SMS, Olivia will ask them if they closed their browser window.
Candidate URLs affected
Candidates must enter in verification codes when they click on the following URLs from their conversation:
Affected URLs
Apply URLs
- Resume Upload URL
- Document Upload URL
- Video Capture URL
- Long list Select Questions URL
- EEO Questions URL
- Candidate Self Update URL
- Follow Up Conversation URL
- Invite to Apply: Talent Community URL
- Conversation Reminders URL
Assessment URLs
- Send Assessment URL
- Assessment Reminder URL
- Share Assessment Result URL
- Send Assessment (Talent) URL
- Share Assessment Result (Talent) URL
- Send Realistic Job Preview URL
Campaign URLs
- Campaign Widget URL
- Message Campaign URL
- Conversation Campaign URL
- Talent Community Campaign URL
- Survey Campaign URL
- Scheduling Campaign URL
- Event Campaign URL
- One Time Message Campaign URL
Event URLs
- My Event Schedule Landing Page URL
- Event Registration Reminders URL
- Event Landing Page URL
- Event Candidate Invitation URL
- One Time Message Campaign URL
Scheduling URLs
- Availability Times for Candidate URL
Reschedule and cancel URLs for interviews are also included.
- Scheduled Interview Reminders URL
- Recorded Interview URL
- Candidate Interview Prep Landing Page URL
Job Search URLs
- Job Alert Results URL
Talent Community URLs
- Talent Community Opt-in URL
Form URLs
- Candidate Form URL
- Talent Community Form URL
Offer URLs
- Candidate Offer URL
Paradox Admins must also enter a verification code when they access any of the above URLs.